Skip to content

docs: clarify Telegram Mini App credential safety - #612

Open
RobQocharyan123 wants to merge 4 commits into
security-alliance:developfrom
RobQocharyan123:RobQocharyan123-patch-1
Open

docs: clarify Telegram Mini App credential safety#612
RobQocharyan123 wants to merge 4 commits into
security-alliance:developfrom
RobQocharyan123:RobQocharyan123-patch-1

Conversation

@RobQocharyan123

Copy link
Copy Markdown

Summary

Clarifies the existing Telegram Mini App guidance by:

  • stating that Mini Apps and support flows must not request Telegram credentials or wallet recovery secrets;
  • directing users to verify unexpected Telegram destinations through an independently published official website or support route; and
  • adding the required minimal contributor metadata using the public GitHub identity only.

Disclosure

I am affiliated with Pointify, a Telegram Mini App publisher. This contribution is non-promotional, adds no Pointify link or product claim, and requests no backlink or specific link attribute.

Validation

  • Compared against the current develop source.
  • Checked open pull requests for duplicate Telegram or Mini App guidance.
  • Both GitHub web commits are Verified.

Add explicit credential and wallet-secret boundaries plus independent route verification.
Register public GitHub-only contributor metadata required for attribution.

@NFTDreww NFTDreww left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Most of this proposed section overlaps with what's already here:

"avoid logging in or providing information to mini apps that redirect outside of Telegram," "triple-check the username," and the support-DM guidance together already cover the "verify unexpected routes out-of-band" and "don't hand credentials to a Mini App" points.

The one thing the current text doesn't do is name wallet secrets explicitly, which matters for audience imo. I suggest folding that specificity into the existing Mini Apps and Support bullets rather than adding a standalone section, this keeps the guide non-redundant and adds a clarifying new point.

Something like:

- Exercise Caution with Mini Apps: Avoid logging in or providing information to mini apps that redirect outside of Telegram. Never enter or send a login code, Two-Step Verification password, seed phrase, private key, or recovery phrase to a Mini App, no legitimate Mini App needs them.

@scode2277 scode2277 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey @RobQocharyan123, thanks for this contribution!

Small note on the attribution first: I updated your role in the list. To be credited as a writer of a page we look for a substantial amount of added content, so that is the only reason for the change. Nothing against what you added, there is just a distinction to make between the two. If you want to land on the writer side, take a section or a topic and build it out, we'll be happy to review it and get it in.

On the PR itself, @NFTDreww left a review as the steward of the framework, as soon as he approves the content, this will be ready to go!

Thanks again 🙏🏻

@github-actions

github-actions Bot commented Aug 27, 2026

Copy link
Copy Markdown
built with Refined Cloudflare Pages Action

⚡ Cloudflare Pages Deployment

Name Status Preview Last Commit
frameworks ✅ Ready (View Log) Visit Preview 7dc80b4

@scode2277 scode2277 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks again @RobQocharyan123 and thanks @NFTDreww for the review!🙏🏻

gtg now @mattaereal!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants